Updated: 24 July 2026
Security Information
No service is “fully secure in every way.” ClearPath uses layered controls and requires continuing updates, monitoring and testing. Report suspected vulnerabilities privately to roy@clearpathsolutions.ie. Do not access another family’s data while testing.
Controls prepared in the release
- Email verification and minimum-password controls.
- Firebase Authentication and household-scoped Firestore rules.
- Revisioned transactions and conflict merging.
- Server-authorised member removal, invitation-code rotation and account-deletion cleanup.
- Authenticated, size-limited AI proxy requests with optional AI consent off by default.
- HTTPS, security headers, frame blocking, MIME-sniffing protection and a content security policy.
- Household-specific offline cache, visible save failures, retry, export and verified restore.
- Firebase App Check client support pending production configuration and staged enforcement.
User security
- Use a unique password and secure the email account used for resets.
- Do not share a family invitation code publicly.
- Review household members regularly and remove former members promptly.
- Store downloaded backups securely and remove old copies.
- Minimise sensitive information.
Pre-launch testing
App Check configuration, Firestore emulator validation, staged regression testing, monitoring, restore tests, dependency review and an independent penetration test remain required before accepting paying users.